Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-45338

Опубликовано: 18 дек. 2024
Источник: debian

Описание

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-golang-x-netfixed1:0.27.0-2package
golang-golang-x-netno-dsabookwormpackage
golang-golang-x-netpostponedbullseyepackage

Примечания

  • https://go-review.googlesource.com/c/net/+/637536

  • https://github.com/golang/go/issues/70906

  • https://pkg.go.dev/vuln/GO-2024-3333

  • https://groups.google.com/g/golang-announce/c/wSCRmFnNmPA/m/Lvcd0mRMAwAJ

  • Fixed by: https://github.com/golang/net/commit/8e66b04771e35c4e4125e8c60334b34e2423effb (v0.33.0)

  • POC: https://github.com/golang/go/issues/70906#issuecomment-2557719304

Связанные уязвимости

CVSS3: 5.3
ubuntu
6 месяцев назад

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

CVSS3: 7.5
redhat
6 месяцев назад

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

CVSS3: 5.3
nvd
6 месяцев назад

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.

CVSS3: 5.3
msrc
5 месяцев назад

Описание отсутствует

CVSS3: 5.3
redos
5 месяцев назад

Уязвимость golang-x-net-devel